-
Bug
-
Resolution: Fixed
-
Low
-
3.4.2
-
9.1
-
Severity 1 - Critical
There was an argument injection vulnerability in SourceTree for Windows introduced through git-lfs. An attacker could create a malicious repository which, after being cloned in SourceTree for Windows and enabled with git-lfs, is able to exploit this issue to gain code execution on the system. This is the result of an incomplete fix for CVE-2020-27955
Affected versions:
- Version 3.4.2 and earlier
Fix
- You can download the latest version of the standard installer or the enterprise installer.
For additional details, see the full advisory
[SRCTREEWIN-13480] RCE via git-lfs in Sourcetree for Windows - CVE-2021-21237
Remote Link | New: This issue links to "Page (Confluence)" [ 847575 ] |
Remote Link | New: This issue links to "Page (Confluence)" [ 846204 ] |
Security | Original: Atlassian Staff [ 10750 ] |
Remote Link | New: This issue links to "Page (Confluence)" [ 537145 ] |
Description |
Original:
There was an argument injection vulnerability in SourceTree for Windows introduced through git-lfs. An attacker could create a malicious repository which, after being cloned in SourceTree for Windows and enabled with git-lfs, is able to exploit this issue to gain code execution on the system. *This is the result of an incomplete fix for CVE-2020-27955*
*Affected versions:* * Version 3.4.2 and earlier *Fix* * You can download the latest version of the [standard installer|https://product-downloads.atlassian.com/software/sourcetree/windows/ga/SourceTreeSetup-3.4.3.exe] or the [enterprise installer|https://product-downloads.atlassian.com/software/sourcetree/windows/ga/SourceTreeSetup-3.4.3.msi]. For additional details, see the [full advisory|https://confluence.atlassian.com/display/SOURCETREEKB/SourceTree+for+Windows+Security+Advisory+27th+January+2021] |
New:
There was an argument injection vulnerability in SourceTree for Windows introduced through git-lfs. An attacker could create a malicious repository which, after being cloned in SourceTree for Windows and enabled with git-lfs, is able to exploit this issue to gain code execution on the system. *This is the result of an incomplete fix for CVE-2020-27955*
*Affected versions:* * Version 3.4.2 and earlier *Fix* * You can download the latest version of the [standard installer|https://product-downloads.atlassian.com/software/sourcetree/windows/ga/SourceTreeSetup-3.3.9.exe] or the [enterprise installer|https://product-downloads.atlassian.com/software/sourcetree/windows/ga/SourcetreeEnterpriseSetup_3.3.9.msi]. For additional details, see the [full advisory|https://confluence.atlassian.com/display/SOURCETREEKB/SourceTree+for+Windows+Security+Advisory+24th+March+2021] |
Description |
Original:
There was an argument injection vulnerability in SourceTree for Windows introduced through git-lfs. An attacker could create a malicious repository which, after being cloned in SourceTree for Windows and enabled with git-lfs, is able to exploit this issue to gain code execution on the system. *This is the result of an incomplete fix for CVE-2020-27955*
*Affected versions:* * Version 3.4.2 and earlier *Fix* * You can download the latest version of the [standard installer|https://product-downloads.atlassian.com/software/sourcetree/windows/ga/SourceTreeSetup-3.3.9.exe] or the [enterprise installer|https://product-downloads.atlassian.com/software/sourcetree/windows/ga/SourcetreeEnterpriseSetup_3.3.9.msi]. For additional details, see the [full advisory|https://confluence.atlassian.com/display/SOURCETREEKB/SourceTree+for+Windows+Security+Advisory+27th+January+2021] |
New:
There was an argument injection vulnerability in SourceTree for Windows introduced through git-lfs. An attacker could create a malicious repository which, after being cloned in SourceTree for Windows and enabled with git-lfs, is able to exploit this issue to gain code execution on the system. *This is the result of an incomplete fix for CVE-2020-27955*
*Affected versions:* * Version 3.4.2 and earlier *Fix* * You can download the latest version of the [standard installer|https://product-downloads.atlassian.com/software/sourcetree/windows/ga/SourceTreeSetup-3.4.3.exe] or the [enterprise installer|https://product-downloads.atlassian.com/software/sourcetree/windows/ga/SourceTreeSetup-3.4.3.msi]. For additional details, see the [full advisory|https://confluence.atlassian.com/display/SOURCETREEKB/SourceTree+for+Windows+Security+Advisory+27th+January+2021] |
Remote Link | New: This issue links to "Page (Confluence)" [ 532576 ] |
Remote Link | New: This issue links to "Page (Confluence)" [ 532672 ] |
CVSS Score | New: 9.1 | |
Fix Version/s | New: 3.4.3-beta [ 94713 ] | |
Affects Version/s | New: 3.4.2 [ 94691 ] | |
Affects Version/s | Original: 3.3.9 [ 92303 ] | |
Description |
Original:
There was an argument injection vulnerability in SourceTree for Windows introduced through git-lfs. An attacker could create a malicious repository which, after being cloned in SourceTree for Windows and enabled with git-lfs, is able to exploit this issue to gain code execution on the system.
*Affected versions:* * Version 3.3.9 and earlier *Fix* * You can download the latest version of the [standard installer|https://product-downloads.atlassian.com/software/sourcetree/windows/ga/SourceTreeSetup-3.3.9.exe] or the [enterprise installer|https://product-downloads.atlassian.com/software/sourcetree/windows/ga/SourcetreeEnterpriseSetup_3.3.9.msi]. For additional details, see the [full advisory|https://confluence.atlassian.com/display/SOURCETREEKB/SourceTree+for+Windows+Security+Advisory+27th+January+2021] |
New:
There was an argument injection vulnerability in SourceTree for Windows introduced through git-lfs. An attacker could create a malicious repository which, after being cloned in SourceTree for Windows and enabled with git-lfs, is able to exploit this issue to gain code execution on the system. *This is the result of an incomplete fix for CVE-2020-27955*
*Affected versions:* * Version 3.4.2 and earlier *Fix* * You can download the latest version of the [standard installer|https://product-downloads.atlassian.com/software/sourcetree/windows/ga/SourceTreeSetup-3.3.9.exe] or the [enterprise installer|https://product-downloads.atlassian.com/software/sourcetree/windows/ga/SourcetreeEnterpriseSetup_3.3.9.msi]. For additional details, see the [full advisory|https://confluence.atlassian.com/display/SOURCETREEKB/SourceTree+for+Windows+Security+Advisory+27th+January+2021] |
Resolution | New: Fixed [ 1 ] | |
Status | Original: Needs Triage [ 10030 ] | New: Closed [ 6 ] |